Resource exhaustion in REXML - CVE-2024-43398
Published: September 10, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when parsing XML with multiple deep elements that have same local name attributes. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
Gentoo Linux
Oracle Linux
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Enterprise Storage
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Anolis OS
macOS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
Basesystem Module
openEuler
Ubuntu
Fedora
Software Support App (iOS)
APEX Cloud Platform for Microsoft Azure
Software Support app (Android)
Cognos Analytics Mobile (Android)
Cognos Analytics Mobile (iOS)
IBM Cloud Pak for Watson AIOps
Dell EMC VxRail Appliance
IBM License Metric Tool
rubygem-rss
rubygem-abrt-doc
rubygem-abrt
rubygem-mysql2-doc
rubygem-mysql2
rubygem-io-console
pcs (Red Hat package)
pcs-snmp
pcs
rubygem-typeprof
swiftlint
rubygem-rbs
rubygem-did_you_mean
rubygem-pg-doc
rubygem-pg
rubygem-racc
rubygem-irb
rubygem-power_assert
rubygem-openssl
rubygem-bundler
rubygem-json
ruby2.5-devel
libruby2_5-2_5
ruby2.5-stdlib-debuginfo
libruby2_5-2_5-debuginfo
ruby2.5
ruby2.5-stdlib
ruby2.5-debugsource
ruby2.5-devel-extra
ruby2.5-debuginfo
libruby2.7 (Ubuntu package)
ruby2.7 (Ubuntu package)
rubygem-bigdecimal
ruby-debuginfo
ruby-debugsource
ruby-devel
ruby
ruby-help
ruby-irb
rubygem-rexml
rubygems-devel
rubygems
rubygem-psych
ruby-bundled-gems
ruby-libs
ruby-doc
ruby-default-gems
rubygem-test-unit
dev-ruby/rexml
rubygem-minitest
rubygem-rdoc
rubygem-rake
APEX Cloud Platform for Red Hat OpenShift
IBM Watson Discovery for IBM Cloud Pak for Data
How to mitigate CVE-2024-43398
Software Support App (iOS) - update to 2.0.0
APEX Cloud Platform for Microsoft Azure - update to 01.04.00.00
Software Support app (Android) - update to 2.0.0
Dell EMC VxRail Appliance - addressed in versions 7.0.533, 8.320
IBM License Metric Tool - update to 9.2.37
macOS - addressed in versions 14.8.2 23J126, 15.7.2 24G325, 26.1 25B78
rubygem-rss - update to 0.2.9-139
rubygem-rss - update to 0.3.1-3
rubygem-abrt-doc - update to 0.4.0-1
rubygem-abrt - update to 0.4.0-1
rubygem-mysql2-doc - update to 0.5.5-1
rubygem-mysql2 - update to 0.5.5-1
rubygem-io-console - update to 0.5.7-139
rubygem-io-console - update to 0.7.1-3
pcs (Red Hat package) - addressed in versions 0.10.12-6.el8_6.6, 0.10.15-4.el8_8.3, 0.10.18-2.el8_10.2
pcs-snmp - update to 0.10.18-2.0.1
pcs - update to 0.10.18-2.0.1
rubygem-typeprof - update to 0.15.2-139
rubygem-typeprof - update to 0.21.9-3
swiftlint - update to 0.57.1-1.fc42
Cognos Analytics Mobile (Android) - update to 1.1.20
Cognos Analytics Mobile (iOS) - update to 1.1.20
rubygem-rbs - update to 1.4.0-139
rubygem-did_you_mean - update to 1.5.0-139
rubygem-pg-doc - update to 1.5.4-1
rubygem-pg - update to 1.5.4-1
rubygem-racc - update to 1.7.3-3
rubygem-irb - update to 1.13.1-3
rubygem-power_assert - update to 2.0.3-3
rubygem-openssl - update to 2.2.1-139
rubygem-bundler - update to 2.2.32-139
rubygem-json - update to 2.5.1-139
ruby2.5-devel - update to 2.5.9-150000.4.32.1
libruby2_5-2_5 - update to 2.5.9-150000.4.32.1
ruby2.5-stdlib-debuginfo - update to 2.5.9-150000.4.32.1
libruby2_5-2_5-debuginfo - update to 2.5.9-150000.4.32.1
ruby2.5 - update to 2.5.9-150000.4.32.1
ruby2.5-stdlib - update to 2.5.9-150000.4.32.1
ruby2.5-debugsource - update to 2.5.9-150000.4.32.1
ruby2.5-devel-extra - update to 2.5.9-150000.4.32.1
ruby2.5-debuginfo - update to 2.5.9-150000.4.32.1
rubygem-bundler - update to 2.5.16-3
libruby2.7 (Ubuntu package) - update to 2.7.0-5ubuntu1.16
ruby2.7 (Ubuntu package) - update to 2.7.0-5ubuntu1.16
rubygem-json - update to 2.7.1-3
rubygem-bigdecimal - update to 3.0.0-139
ruby-debuginfo - update to 3.0.3-139
ruby-debugsource - update to 3.0.3-139
ruby-devel - update to 3.0.3-139
ruby - update to 3.0.3-139
ruby-help - update to 3.0.3-139
ruby-irb - update to 3.0.3-139
APEX Cloud Platform for Red Hat OpenShift - update to 03.01.02.00
rubygem-bigdecimal - update to 3.1.5-3
rubygem-rexml - update to 3.2.5-139
rubygems-devel - update to 3.2.32-139
rubygems - update to 3.2.32-139
rubygem-psych - update to 3.3.2-139
ruby - update to 3.3.5-3
ruby-bundled-gems - update to 3.3.5-3
ruby-devel - update to 3.3.5-3
ruby-libs - update to 3.3.5-3
ruby-doc - update to 3.3.5-3
ruby-default-gems - update to 3.3.5-3
ruby - addressed in versions 3.3.5-14.fc40, 3.3.5-14.fc41, 3.3.5-14.fc42
rubygem-rexml - update to 3.3.6-3
rubygem-test-unit - update to 3.3.7-139
dev-ruby/rexml - update to 3.3.9
rubygem-rbs - update to 3.4.0-3
rubygems-devel - update to 3.5.16-3
rubygems - update to 3.5.16-3
rubygem-test-unit - update to 3.6.1-3
IBM Cloud Pak for Watson AIOps - update to 4.8.0
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 4.8.7, 5.0.3, 5.1.0
rubygem-psych - update to 5.1.2-3
rubygem-minitest - update to 5.14.2-139
rubygem-minitest - update to 5.20.0-3
rubygem-rdoc - update to 6.3.3-139
rubygem-rdoc - update to 6.6.3.1-3
rubygem-rake - update to 13.0.3-139
rubygem-rake - update to 13.1.0-3
External References
Related Security Bulletins
- Denial of service in REXML gem
- Fedora 42 update for ruby
- Fedora 41 update for ruby
- openEuler update for ruby
- Fedora 40 update for ruby
- Red Hat Enterprise Linux 8 update for pcs
- Red Hat Enterprise Linux 8 update for pcs
- Red Hat Enterprise Linux 8 update for pcs
- Multiple vulnerabilities in IBM License Metric Tool
- Red Hat Enterprise Linux 8 update for the ruby:3.3 module
- Red Hat Enterprise Linux 9 update for the ruby:3.3 module
- Multiple vulnerabilities in Oracle Linux
- IBM Watson Discovery update for Ruby REXML
- SUSE update for ruby2.5
- Multiple vulnerabilities in IBM Cognos Analytics Mobile (Android)
- Multiple vulnerabilities in IBM Cognos Analytics Mobile (iOS)
- Multiple vulnerabilities in IBM Cloud Pak for AIOps
- Fedora 42 update for swiftlint
- Ubuntu update for ruby2.7
- Multiple vulnerabilities in IBM Software Support app
- Anolis OS update for pcs
- Anolis OS update for ruby:3.3 module
- Multiple vulnerabilities in Dell VxRail Appliance
- Multiple vulnerabilities in Dell VxRail Appliance 7.x
- APEX Cloud Platform for Microsoft Azure update for third-party components
- Red Hat Enterprise Linux 9 update for the ruby:3.1 module
- Multiple vulnerabilities in Dell APEX Cloud Platform for Red Hat OpenShift
- Gentoo update for REXML
- Multiple vulnerabilities in Apple macOS Tahoe
- Multiple vulnerabilities in macOS Sequoia
- Multiple vulnerabilities in Apple macOS Sonoma